Frameworks

What is PHI (protected health information)?

In short

PHI is protected health information: individually identifiable health information held or transmitted by a HIPAA covered entity or business associate, in any form or medium. ePHI is the electronic subset, and it is what the Security Rule governs. The definition is at 45 CFR §160.103.

Last updated

Definition

Protected health information is individually identifiable health information that a covered entity or business associate creates, receives, maintains or transmits, in any form or medium. Individually identifiable health information is information about a person’s health or condition, the care they received, or payment for that care, which identifies them or could reasonably be used to identify them.

Background

Two things have to be true for data to be PHI. It has to be health information, which the regulation reads broadly: diagnoses and treatment notes, of course, but also the fact of an appointment, a prescription, a claim, or a payment. And it has to be identifiable, either directly or because the remaining detail could reasonably identify the person. Identity travels on more than a name. The de-identification safe harbor at 45 CFR §164.514(b)(2) lists the identifiers that have to be removed before information is treated as de-identified, and that list is the practical guide to what makes health data identifiable: names; geographic subdivisions smaller than a state; all dates relating to an individual other than the year; telephone and fax numbers; email addresses; Social Security numbers; medical record numbers; health plan beneficiary numbers; account numbers; certificate and license numbers; vehicle identifiers and serial numbers including license plates; device identifiers and serial numbers; web URLs; IP addresses; biometric identifiers including fingerprints and voiceprints; full-face photographs and comparable images; and any other unique identifying number, characteristic or code. Removing them is not sufficient on its own: the safe harbor also requires that you have no actual knowledge the remaining information could identify the person. The alternative route is a documented determination by a qualified expert under §164.514(b)(1). HIPAA also carves things out of PHI by definition: education records covered by FERPA, employment records an employer holds in its role as employer, and information about a person who has been deceased for more than 50 years.

Why it matters

PHI is the scope boundary for a HIPAA program. The Security Rule applies to electronic PHI, and §164.306(c) applies its standards to all of it, so every system that holds ePHI is in scope for your risk analysis, access controls and audit logging. Teams usually underestimate this. Support tickets with a patient’s name and the reason for a visit are PHI. A scheduling record that pairs a person with a specialty clinic is PHI. Application logs that capture a request body are PHI if that body carried any. Treating a free-text field as harmless is how ePHI ends up in a system nobody listed. Going the other way, de-identified information is not PHI, so a genuinely de-identified dataset is outside HIPAA, which is why the safe harbor is worth getting right rather than approximating.

Step by step

  1. List every place health information enters your systems, including forms, integrations, uploads, email and support channels.
  2. For each store, decide whether what it holds is identifiable, and document why.
  3. Classify the result and label the systems that hold PHI, so later decisions about access and logging are made against a known list.
  4. Keep PHI out of the places that do not need it: logs, analytics, test and staging environments, and screenshots attached to tickets.
  5. Where you need data for analysis, de-identify properly under §164.514(b) rather than dropping the obvious fields and calling it anonymous.

Examples

  • A list of patient names with appointment dates and the clinic they attended is PHI, with no diagnosis anywhere in it.
  • A billing export containing member numbers and procedure codes is PHI, because the member number identifies the person.
  • An aggregate count of procedures by state and year, with no small cells that single anyone out, is not PHI.
  • A fitness app’s step counts, collected directly from consumers with no provider involved, are health data but usually not PHI, because HIPAA reaches covered entities and business associates rather than all health data.

Common mistakes

  • Thinking PHI means a diagnosis. The fact that someone is a patient, and payment information about their care, both count.
  • Assuming removing names is de-identification. Dates, small geographies, device identifiers and free text can all re-identify a person.
  • Letting ePHI flow into logs, analytics or a staging database, which brings those systems into Security Rule scope.
  • Using the word anonymized to describe data that has only been pseudonymized, which keeps it inside HIPAA while the team believes it is outside.

FAQ

What is the difference between PHI and ePHI?

PHI is protected health information in any form, including paper and speech. ePHI is PHI created, stored or transmitted electronically, and it is what the HIPAA Security Rule governs.

How many PHI identifiers are there?

The de-identification safe harbor at §164.514(b)(2) lists the identifier types that must be removed, ending with a catch-all for any other unique identifying number, characteristic or code. That list is about de-identification rather than a definition of PHI, so treat it as guidance on what makes data identifiable.

Is a name on its own PHI?

Not by itself. It becomes PHI when it is held by a covered entity or business associate in a context that connects the person to health care, a health condition, or payment for care, which a patient list does.

Is de-identified data still PHI?

No. Information de-identified under §164.514(b), either through the safe harbor or an expert determination, is not PHI and the HIPAA rules do not restrict its use. A limited data set is not de-identified and remains PHI.

Does Keel’s HIPAA framework score the de-identification rules?

No. De-identification and limited data sets govern an act an organization elects to perform, so Keel scores the provisions that impose duties regardless. What is in and out is written down on the HIPAA scope page.

Next step

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.